CVE-2021-3007: Critical severity getlaminas Laminas-http vulnerability
DISPUTED Laminas Project laminas-http before 2.14.2, and Zend Framework 3.0.0, has a deserialization vulnerability that can lead to remote code execution if the content is controllable, related to the destruct method of the Zend\Http\Response\Stream class in Stream.php. NOTE: Zend Framework is no longer supported by the maintainer. NOTE: the laminas-http vendor considers this a "vulnerability in the PHP language itself" but has added certain type checking as a way to prevent exploitation in (unrecommended) use cases where attacker-supplied data can be deserialized.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/laminas/laminas-httpto a version that resolves this vulnerability.Fixed in 2.14.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-3007.
What is the severity level of CVE-2021-3007?
The severity level of CVE-2021-3007 is critical (9.8).
Which software packages are affected by CVE-2021-3007?
The affected software packages are Laminas Project laminas-http before version 2.14.2 and Zend Framework version 3.0.0.
How can CVE-2021-3007 be exploited?
CVE-2021-3007 can be exploited through a deserialization vulnerability in the __destruct method of the Zend\Http\Response\Stream class in Stream.php.
How can I fix CVE-2021-3007?
To fix CVE-2021-3007, update Laminas Project laminas-http to version 2.14.2 or higher and update Zend Framework to version 3.0.1 or higher.